feat: workspace trust disclosure and PYTHINKER_CODE_TRUST_WORKSPACE - #337
Conversation
Headless runs can set the variable instead of answering the trust prompt; the untrust route now reports the effective trust state.
The trust prompt and SDK trust info now disclose gated MCP servers with their config origins, additional directory grants, and the project instruction sources (AGENTS.md, skills, agent profiles) that load on trust.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. 🗂️ Base branches to auto review (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: PyModel/pythinker-code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
commit: |
pnpm audit reported 34 advisories (15 high) against the resolved tree: undici, fast-uri, ip-address, dompurify, serialize-javascript, markdown-it, brace-expansion, and electron. Raise the existing override floors and add scoped ones (fast-uri pinned to ^3, brace-expansion per major, markdown-it capped <15 because vitepress-plugin-llms deep-imports markdown-it/lib/token.mjs, removed in 15). Bump electron 43.4.0 to 43.5.0 (GHSA high, patched >=43.5.0). Refresh the flake pnpmDeps hash for the new lockfile.
check-artifacts.mjs pinned DOMPurify 3.4.14, ip-address 10.5.0, fast-uri 3.1.5, and brace-expansion 1.1.18/2.1.4/5.0.9 as safe floors — every one of them inside the advisory ranges fixed by the dependency bump. Raise them to 3.4.16 / 10.7.1 / 3.1.8 / 1.1.21 / 2.1.7 / 5.0.12, and make the Monaco resolved-version check a floor so future patch bumps do not rebreak it.
Requirement or Bug
Make workspace trust transparent: a headless trust opt-out and a prompt that shows what trusting would activate.
Bug Reproduction Steps
N/A (features).
Root Cause
Headless runs had no way to pre-trust a workspace, and the trust prompt asked for a decision without showing what it would enable. Both addressed at the service layer.
Code Changes
PYTHINKER_CODE_TRUST_WORKSPACE=1env var trusts the current workspace for headless runs without answering the trust prompt; untrust reports the effective state.WorkspaceTrustDisclosureService.getWorkspaceTrustInfogainsorigin,gatedAdditionalDirs,additionalDirSources,warnings, andinstructionSources.env-vars.md,mcp.mdrows for the new variable and warning text.Impact Scope
packages/agent-core-v2(workspaceTrust domain, program wiring, trust prompt, mcpRegistry),packages/agent-gateway(env trust, untrust report),packages/node-sdk(trust info shape), CLI (cli/v2MCP warning), docs.Checklist
/approve). — No public issue; maintainer work.gen-changesetsskill, or this PR needs no changeset.gen-docsskill, or this PR needs no doc update.